检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
By default, a VPN gateway uses two EIPs.
Scenario Figure 1 shows the typical networking where a Huawei Cloud VPN gateway connects to a Hillstone firewall in an on-premises data center in BGP routing mode.
Data Plan Table 1 Data plan Category Item Sangfor Firewall Example Value Example Value for the Huawei Cloud Side VPC Subnets that can communicate with each other 172.16.0.0/24 172.16.1.0/24 192.168.0.0/24 192.168.1.0/24 VPN gateway Gateway IP address 1.1.1.1 Active EIP: 1.1.1.2 Standby
Scenario Figure 1 shows the typical networking where a Huawei Cloud VPN gateway connects to a Hillstone firewall in an on-premises data center in static routing mode.
The Client Log Contains "error:068000A8:asn1 encoding routines:wrong tag" Applicable Client Linux Windows OpenVPN GUI Windows OpenVPN Connect Symptom A client cannot connect to a P2C VPN gateway, and the log contains the following error information: error:068000A8:asn1 encoding routines
Click the P2C VPN Gateways tab, locate the target VPN gateway, and click View Server in the Operation column. Upload a CA certificate.
Reference link: Creating Enterprise Edition VPN Connections Creating a Classic VPN Connection What Are a VPC, a VPN Gateway, and a VPN Connection? Parent topic: Basic Concepts
Create two VPN connections between the VPN gateway (active EIP and active EIP 2) and the customer gateway.
Table 2 Parameters for creating a customer gateway Parameter Description Value Name Name of the Huawei VPN gateway. cgw-hw01 IP address Active EIP of the Huawei Cloud VPN gateway. 1.1.1.2 Configure the user gateway corresponding to the standby EIP of the Huawei Cloud VPN gateway by
Click the P2C VPN Gateways tab, locate the target VPN gateway, and click View Server in the Operation column. On the Server tab page, view the server ID in the Basic Information area, and view the server port and protocol in the Advanced Settings area.
The Client Log Contains "Cannot load CA certificate file [[INLINE]](no entries were read)" Applicable Client Linux Windows OpenVPN GUI Symptom A client cannot connect to a P2C VPN gateway, and the log contains the following error information: Cannot load CA certificate file [[INLINE
In the P2C VPN gateway list, locate the target P2C VPN gateway, and click View Server in the Operation column. On the Server tab page of the VPN gateway, click Replace. In the displayed dialog box, click Upload in the drop-down list box. Upload the new server certificate to CCM.
In the P2C VPN gateway list, locate the target P2C VPN gateway, and click View Server in the Operation column. On the Server tab page, view the issuer information of the client CA certificate.
Click the P2C VPN Gateways tab, locate the target VPN gateway, and click View Server in the Operation column. On the Server tab page, view the server ID in the Basic Information area, and view the server port and protocol in the Advanced Settings area.
In the P2C VPN gateway list, locate the target P2C VPN gateway, and click View Server in the Operation column. Upload CA certificates.
The Client Log Contains "Error message: ovpnagent:request error" Applicable Client Windows OpenVPN Connect Symptom A client cannot connect to a P2C VPN gateway, and the log contains the following error information: Error message: ovpnagent:request error Possible Causes The OpenVPN
The Client Log Contains "X509::parse_pem: error in cert::error:0480006C:PEM routines::no start line" Applicable Client Linux Windows OpenVPN GUI Symptom A client cannot connect to a P2C VPN gateway, and the log contains the following error information: X509::parse_pem: error in cert
The Client Log Contains "certReadError" Applicable Client Linux Windows OpenVPN GUI Symptom A client cannot connect to a P2C VPN gateway, and the log contains the following error information: certReadError Possible Causes In certificate authentication mode, the client configuration
In the P2C VPN gateway list, locate the target P2C VPN gateway, and click View Server in the Operation column. On the Server tab page, view the encryption algorithm and authentication algorithm of the server in the Advanced Settings area.
The Client Log Contains "Unrecognized option or missing or extra parameter(s) in xxx.ovpn:108: data-ciphers (2.4.12)" Applicable Client Linux Symptom A client cannot connect to the VPN gateway, and the client log contains the following error message: Unrecognized option or missing